RHSA-2020:4056: Important: qemu-kvm security update
Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM.Security Fix(es): QEMU: usb: out-of-bounds r/w access issue while processing usb packets (CVE-2020-14364) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/qemu-kvmto a version that resolves this vulnerability.Fixed in 0.12.1.2-2.506.el6_10.8 - Upgrade
Upgrade
redhat/qemu-guest-agentto a version that resolves this vulnerability.Fixed in 0.12.1.2-2.506.el6_10.8 - Upgrade
Upgrade
redhat/qemu-imgto a version that resolves this vulnerability.Fixed in 0.12.1.2-2.506.el6_10.8 - Upgrade
Upgrade
redhat/qemu-kvm-debuginfoto a version that resolves this vulnerability.Fixed in 0.12.1.2-2.506.el6_10.8 - Upgrade
Upgrade
redhat/qemu-kvm-toolsto a version that resolves this vulnerability.Fixed in 0.12.1.2-2.506.el6_10.8
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:4056?
The severity of RHSA-2020:4056 is classified as important.
How do I fix RHSA-2020:4056?
To fix RHSA-2020:4056, you should update the affected packages to version 0.12.1.2-2.506.el6_10.8 or later.
What are the affected packages for RHSA-2020:4056?
The affected packages for RHSA-2020:4056 include qemu-kvm, qemu-guest-agent, qemu-img, qemu-kvm-debuginfo, and qemu-kvm-tools.
Is RHSA-2020:4056 a local or remote vulnerability?
RHSA-2020:4056 is considered a local vulnerability.
What component is primarily impacted by RHSA-2020:4056?
The primary component impacted by RHSA-2020:4056 is the QEMU user-space component.